Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi OS ServerAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |
| Aplazada | Alta (8.2) | 0.39% | — | UI Unifi ConnectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 0.42% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi Network ApplicationAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. | |
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Cisco Unified Intelligence CenterAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Communications Unified Inventory Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0-7.8.0 and 8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Communications Unified Inventory Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component). Supported versions that are affected are 7.5.0-7.5.1, 7.6.0-7.8.0 and 8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.7) | 0.35% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Media (6.8) | 0.29% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Pendiente de análisis | Media (6.1) | 0.34% | — | SWC Html MinifierAIGO HtmlAI | 11/8/2026 | 18/9/2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the… | |
| Aplazada | Media (5.3) | 0.33% | — | Yithemes Yith Woocommerce Zoom MagnifierAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | |
| Analizada | Media (6.5) | 0.64% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 5/8/2026 | 16/9/2026 | — | |
| Analizada | Alta (8.8) | 0.73% | 💥 PoC | Cisco Unified Computing System | 5/8/2026 | 31/8/2026 | — | |
| Analizada | Alta (8.8) | 0.74% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could… | |
| Analizada | Baja (2.3) | 0.48% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized… |